Managed ITServices
Statistics

Ransomware Statistics 2024: A Complete Review (Updated 2026)

Ransomware in 2024 was defined by a striking paradox: attack volumes hit record highs while ransom payments dropped sharply.

Ransomware in 2024 was defined by a striking paradox: attack volumes hit record highs while ransom payments dropped sharply. Threat actors launched at least 5,263 ransomware attacks worldwide, the highest annual total since monitoring began, according to the NCC Group Annual Cyber Threat Monitor Report published in January 2025. Yet victims paid roughly 35% less than the year before, with total cryptocurrency payments landing at $892 million per the Chainalysis 2026 Crypto Crime Report. This article compiles the most important ransomware statistics from 2024, drawn exclusively from reports published in 2025 and 2026, and traces how the threat has continued to evolve since then.

Key Ransomware Statistics From 2024

Ransomware Statistics 2024: A Complete Review (Updated 2026) infographic

Record Attack Volume Despite Law Enforcement Pressure

The 5,263 attacks tracked by NCC Group in 2024 represented a meaningful increase over the prior year, even as international law enforcement landed significant blows against major ransomware operations. The takedown of LockBit infrastructure in February 2024 disrupted the group's operations but did not remove it from the landscape entirely. NCC Group still attributed 526 attacks, or 10% of the annual total, to LockBit affiliates. RansomHub emerged as the dominant threat actor in the second half of the year, claiming 501 attacks and filling much of the vacuum left by LockBit's disruption.

The geographic concentration of attacks remained heavily skewed toward Western economies. North America absorbed over 55% of all recorded ransomware incidents, and when combined with Europe, that share rose to 79%. However, NCC Group noted rising activity in Asia, South America, and Oceania, signaling that ransomware operators were broadening their target base.

The industrial sector bore the heaviest burden, accounting for 27% of all attacks (1,424 incidents) and experiencing a 15% year-over-year increase. Manufacturers, utilities, and logistics companies are especially vulnerable because operational downtime directly translates into financial pressure to pay, making them high-value targets for extortion.

The Payment Paradox: More Attacks, Less Revenue

One of the most encouraging ransomware statistics from 2024 is the sharp decline in payments. According to the Chainalysis 2026 Crypto Crime Report, total on-chain ransomware payments fell to $892 million in 2024 after peaking at roughly $1.37 billion in 2023. That 35% drop happened even as attack volumes climbed, pointing to a meaningful shift in how organizations respond to ransomware incidents.

The Verizon 2025 DBIR reinforced this trend. Among the breaches it analyzed during the November 2023 to October 2024 reporting window, 64% of victim organizations declined to pay, compared to 50% just two years earlier. The median payment among those who did pay dropped to $115,000, down from $150,000 in the prior period.

Several factors drove the payment decline. Improved backup strategies meant more organizations could recover without the decryption key. The FBI distributed thousands of decryption keys to ransomware victims, helping organizations avoid over $800 million in potential payments since 2022. And growing awareness that payment does not guarantee data recovery, nor prevent future attacks, shifted the calculus for many leadership teams.

That said, the picture was not uniformly positive. Sophos found that among organizations surveyed for its State of Ransomware 2025 report, the median ransom payment reached $1.26 million, and median demands hit $2.75 million. The gap between the Verizon and Sophos figures reflects differences in methodology and sample composition, but both reports agree on the directional trend: fewer organizations are paying, yet those that do are paying substantial sums.

Small Businesses in the Crosshairs

Perhaps the most alarming finding in the 2024 data is the outsized impact on small and medium-sized businesses. The Verizon 2025 DBIR found that ransomware was present in 88% of breaches affecting SMBs, compared to 39% at larger organizations. That gap is enormous, and it reflects a structural disadvantage: smaller companies typically lack dedicated security teams, 24/7 monitoring, and the incident response playbooks that larger enterprises maintain.

The financial impact compounds the problem. Recovery costs averaging $3.12 million, as reported by Sophos, can be existential for a company with $10 million or $20 million in annual revenue. Downtime, lost business, regulatory penalties, and reputational damage pile on top of the direct costs of remediation. For many SMBs, a ransomware attack is not just a security event but a business survival event.

The encryption rate adds another dimension. Sophos found that 66% of ransomware attacks in 2024 successfully encrypted the victim's data. While that figure was lower than in prior years, suggesting that detection and response capabilities are improving, it still means that two-thirds of targeted organizations lost access to their files. Organizations that relied on backups for recovery reported using them in 73% of cases, underscoring the importance of robust, tested, and isolated backup systems.

The Rise of Dual Extortion and Data Theft

By 2024, pure encryption attacks had become the exception rather than the rule. Most ransomware operators adopted dual-extortion tactics, combining file encryption with data theft and the threat of public exposure on leak sites. This evolution means that even organizations with perfect backups face the risk of sensitive data being published or sold.

The NCC Group report documented a steady increase in leak-site postings throughout 2024, with threat actors using data exposure as leverage regardless of whether the victim could restore systems from backups. The tactic is especially damaging in regulated industries such as healthcare and financial services, where data exposure triggers mandatory breach notifications, regulatory investigations, and potential fines.

Sophos reported that the median ransom demand of $2.75 million in 2024 often reflected the perceived value of stolen data as much as the cost of operational disruption. Attackers increasingly priced their demands based on the sensitivity of exfiltrated files, revenue of the victim organization, and the potential regulatory consequences of a data leak.

How Numbers Evolved in 2025-2026

The trends visible in the 2024 data have intensified. The Chainalysis 2026 report shows that total ransomware payments fell further to $820 million in 2025, an 8% decline from the revised 2024 figure, while the share of victims who paid potentially reached an all-time low of 28%. Interestingly, the median payment climbed 368% to $59,556, suggesting that opportunistic small-dollar payments dried up while a smaller number of high-value targets accounted for a larger share of the total.

The Verizon 2026 DBIR found ransomware present in 48% of breaches, up from 44% in the 2025 edition, continuing the upward trajectory. NCC Group's data for 2025 showed another record year for global ransomware volume. And the FBI's IC3 2025 report logged 3,611 ransomware complaints with $32.3 million in reported losses, up from 3,156 complaints and $12.5 million in 2024.

The ransomware ecosystem has also fragmented. Dozens of new groups entered the space in 2025 and 2026, and the collapse of established brands like LockBit and ALPHV/BlackCat created openings that smaller, more agile operators quickly filled. The barrier to entry continues to drop as ransomware-as-a-service platforms make sophisticated tools available to less technically skilled affiliates.

Recovery costs have begun to decline modestly. Sophos reported mean recovery costs falling from $3.12 million in 2024 to $1.84 million in 2025, driven in part by faster detection and better-prepared incident response processes. But the overall trend remains clear: ransomware is becoming more frequent, more distributed across threat actors, and more difficult to defend against without dedicated security resources.

How Managed IT Services Can Help

The ransomware statistics from 2024 make a compelling case for proactive, professionally managed security. With 88% of SMB breaches involving ransomware and mean recovery costs exceeding $3 million, the risk of operating without dedicated security resources has never been higher.

Managed IT services providers address the exact vulnerabilities that ransomware operators exploit. Continuous monitoring catches suspicious activity before encryption begins. Managed endpoint detection and response tools can isolate compromised machines in seconds. Regular patch management closes the known vulnerabilities that threat actors use for initial access. And tested, isolated backup systems ensure that organizations can recover without paying a ransom.

For small and medium-sized businesses that cannot justify building an in-house security operations center, a managed IT services partner provides enterprise-grade protection at a fraction of the cost. The 2024 data is unambiguous: organizations that invest in layered defenses, rapid detection, and professional incident response are far more likely to survive a ransomware attack with their business intact.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 26, 2026 · 8 min read